CYBER CRIME & CYBER SECURITY TRENDS IN AFRICA THE STATE OF CYBER CRIME LEGISLATION IN AFRICA – AN OVERVIEW Council of Europe/Project Cybercrime@Octopus1 1. Introduction: Why Should Countries of Africa Adopt Legislation on Cyber Crime and Electronic Evidence? Cyber crime is not only a question of attacks against the confidentiality, integrity and availability of computer data and systems but against the core values and the human development potential of societies increasingly relying on information technology. In the light of this, governments cannot remain passive; they have the obligation to protect society and individuals against crime. In practice, however, governments face serious challenges: • while millions of attacks against computers and data are recorded each day worldwide, only a small fraction of cyber crime2 – that is, offences against and by means of computers – is actually prosecuted and adjudicated; • moreover, evidence in relation to any crime is increasingly available in electronic form on computer systems or storage devices and needs to be secured for criminal proceedings.3 Criminal investigations not relying on electronic evidence seem to become the exception. An effective criminal justice response is needed. This involves the investigation, prosecution and adjudication of offences against and by means of computer systems and data as well as the securing of electronic evidence in relation to any crime. It also requires efficient international cooperation given the transnational nature of cyber crime and in particular of volatile electronic evidence. 2. A Legal Framework on Cyber Crime and Electronic Evidence: What Is Required? Governments are not only obliged to take effective measures for the prevention and control of cyber crime and other offences involving electronic evidence, but they must also respect human rights and rule of law requirements when doing so. Criminal law is a means to achieve this. Comprehensive legislation covering both substantive law (conduct to be defined as a criminal offence) and procedural law (investigative powers for law enforcement) is the foundation of a criminal justice response. Legislation on cyber crime and electronic evidence needs to meet a number of requirements: • It must be sufficiently (technology) neutral to cater for the constant evolution of technology and crime as it otherwise risks becoming obsolete already by the time it enters into force. • Law enforcement powers must be subject to safeguards to ensure that rule of law and human rights requirements are met. • It must be sufficiently harmonised or at least compatible with the laws of other countries to permit international cooperation, for example, to meet the dual criminality condition. African States preparing legislation on cyber crime may draw on a number of documents to seek guidance. These include in particular the African Union Convention on Cyber Security and Personal Data Protection 1 2 3 The views expressed in this technical report do not necessarily reflect the official position of the Council of Europe or of the Parties to the Budapest Convention on Cyber Crime. Contact: alexander.seger@coe.int Defined here as offences against and by means of computer data and systems in the sense of Articles 2 to 11 of the Budapest Convention on Cyber crime. http://conventions.coe.int/Treaty/en/Treaties/Html/185.htm For example, the recent disputes over the encryption of iPhones were not related to cyber crime but to cases of terrorism and drug trafficking. http://recode.net/2016/04/08/apple-fbi-encryption-battle-shifts-to-new-york/ 49

Select target paragraph3